Security Scan Report: finanso.com

Site favicon
Submitted: Oct 30, 2025, 1:56:28 PMCompleted: Oct 30, 2025, 1:57:53 PMpubliccompleted
Loading additional data...

Summary

This website contacted 12 IPs in 2 countries across 5 domains to perform 48 HTTP transactions. The main domain is finanso.com and was registered NaN years ago.

Submitted URL: https://finanso.com/us/citi/

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Impersonates Citibank on an unrelated domain; high‑risk phishing site.

Risk Factors
Brand impersonation/typosquatting on a non‑official domain
UNRANKED domain presenting a major financial brand
Potential social‑engineering to harvest personal or financial information
Domain age information unavailable

Details

Page Title

Citi — About Bank, Reviews, Hotline, Customer Service

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

other

(71%)

Domain Information

The domain name 'finanso.com' uses the commercial generic top-level domain (.com) and has no subdomain. Its registrable label 'finanso' stretches across 7 characters split between three vowels and four consonants. Breaking it apart gives three words: fin, an, so. Expect 2 characters per word on average. The linguistic tilt is Breton for 'fin'. It also appears in German and Slovenian contexts. Overall, 'finanso.com' reads as Breton.

Screenshot

Security scan screenshot of https://finanso.com/us/citi/

Page Load Overview

50.23s
Total Load Time
48
HTTP Requests
5
Domains
2.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en-US
Text Length:13,582 chars
Detector Agreement:100%

Website Classification

Primary Category

other71% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

other
71%
legitimate website
38%
e-commerce
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4142.250.186.106United States
AS15169GOOGLE
4104.26.3.45United States
AS13335CLOUDFLARENET
4104.26.2.45United States
AS13335CLOUDFLARENET
4216.58.206.67United States
AS15169GOOGLE
4172.67.75.48United States
AS13335CLOUDFLARENET
42a00:1450:4001:827::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
42606:4700:20::681a:32dUnited States
AS13335CLOUDFLARENET
4142.250.185.163United States
AS15169GOOGLE
42606:4700:20::ac43:4b30United States
AS13335CLOUDFLARENET
42a00:1450:4001:811::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
4812--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T135442AAAA38412BD680387F4E061EA5DF20F78FDEF638FA9F6DC554097C15E91CA1904

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:I9kpBHuQxEY4hReupOV1uuVr7UEix310Ktz:FyP310Kd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:253999:IADgdQQkwQHaCGUSYJQiAqQlGkTSQxkDALBKQDJWlAGIhUG4BoBAEkJBPxomDPgoJHCCHJZSZkAAhjswaYAh5BHKAsBgRYRN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:000000ffff9fffff
Perceptual Hash:bc4343bcc98cb9c3
Difference Hash:11c4c4232e3e2e56
Wavelet Hash:000000df9f8f9fff
Color Hash:#c1d279

Scan History

Scan history not available

Unable to load historical scan data